How we research and compare penetration testing offers
This page explains how the current comparison was built: which offers are included, how evidence is recorded, how prices and terms are made comparable, how Purchase Checks reach a finding, and how corrections work. The full comparison was checked on ; specific terms were rechecked on .
This site may contain affiliate or referral links. If you buy through one, we may be compensated. Read how we make money.
The current sample
The comparison covers selected offers from 8 companies: 12 managed testing entries and 3 scanning tools, supported by 15 provider source pages.
Every entry in the current sample:
- is a specific offer described on the provider’s own website;
- covers web application or API testing, or is a scanning tool a buyer may consider alongside a test; and
- has a public page describing its scope and at least one of its price basis, retest terms or timing.
These are properties every current entry shares, not a claim of completeness. The sample is not a census of the market, being included is not an endorsement, and payment plays no part in inclusion.
What one entry represents
Each entry is a specific offer, not a company. One company can sell human testing, AI testing and scanning as separate products, and one entry can contain several packages, such as tiers or black-box and gray-box versions. Facts are recorded against the package they apply to.
Grouping and order
Managed testing offers are grouped by who leads the testing:
- Tests led by people: human testers carry out the testing.
- Tests led by AI: an AI system performs much of the testing, with a human role that differs from offer to offer.
Scanning tools you operate yourself are shown separately. Within each group, companies are listed A to Z, and a company with more than one entry keeps its entries together. Nothing is ranked, scored or rated.
Source observations
Every fact comes from a source observation, which records:
- the exact offer and package;
- the source page, and the section of it that states the fact;
- the date that fact was checked;
- the type of evidence;
- what the fact applies to, such as a single package or plan; and
- any limitation or conflict.
| Evidence type | Meaning |
|---|---|
| Provider-published | The provider’s own public page states this. It is not an assessment of testing quality. |
| Confirmed in writing | The provider confirmed this in writing. It applies only to the recipient and brief named. |
| Sample inspected | We inspected a sample deliverable. It supports only what the sample shows. |
| Buyer-reported | A buyer reported this. It describes one purchase, not every purchase. |
| Documented purchase outcome | A documented purchase shows this outcome for that purchase. |
All reported offer facts in the current comparison are provider-published. The other types are recorded only when that evidence exists, and each supports only what was actually checked. These labels identify the evidence; they are not a service-quality score or a certification of a company. Our calculations and Purchase Check findings are derived analysis, shown separately from source observations.
Applicable evidence
A fact is used only where it applies. Before a fact supports a comparison cell or a finding, it must concern the same offer and package, the same kind of buyer, the same period, the same scope and the same billing basis. A term stated for one package is not carried over to another.
Dates
Each fact carries the date it was checked, and pages show when the comparison was checked, never when the site was built. Four dates have separate meanings: when a source was checked, when a finding was produced, when a page was last meaningfully edited and when that page was first published. A partial recheck changes only the dates for the facts rechecked; it does not refresh the entire comparison.
Prices and commitments
- Prices are in US dollars for the stated package and unit, such as per test, per target or per year.
- The kind of price is kept: a fixed advertised price, a starting price, a promotion, a price set by the provider’s plan calculator, or quote required. Quoted, contracted and paid prices would be labeled as such; the current comparison contains none.
- Starting-price conditions and required additions, such as a separate platform charge, stay beside the price.
- An annual price stays annual. It is not converted into a monthly figure, and a minimum term is shown as stated.
- An unknown fee stays unknown. It is never treated as zero, so no total is given while a required cost is missing.
- A promotional price is shown only with its conditions and expiry, and an expired promotion is never shown as a current price.
Retesting and timing
Retest terms are recorded in parts: how many retests are included, what starts the window, whether the deadline applies to requesting the retest or to completing it, the human role, and any exclusions or contract cutoff.
Timing keeps the stages of a project apart: booking or start, active testing, the assessment window, first findings, the final report and retesting. A provider’s statement about one stage is not used for another.
Unknowns and conflicts
“Not stated” means the detail was not found in the sources reviewed. It is never read as a “no” or as zero.
When two of a provider’s own sources disagree about the same applicable term, both statements are shown, and the next step is to ask the provider for the applicable term in writing. We do not silently resolve a disagreement by choosing the more attractive term. The current comparison identifies conflicting statements about Cobalt’s unused Enterprise credits and differing published estimates for Astra’s manual testing duration. The comparison names the sources and the estimate shown; the provider must confirm the terms for the buyer’s agreement.
Purchase Checks
A Purchase Check tests one condition of an example purchase against one offer’s published terms. Every check follows the same sequence:
- Requirement. One condition from the brief, recorded as mandatory, preferred or assumed.
- Applicable evidence. The observations that apply to that offer, package and condition.
- Rule or calculation. A small, fixed rule, or arithmetic on published figures.
- Finding. One of five states, with the reason.
- Next question. What is still open, written as a question for the provider.
- Revision condition. The evidence that would change the finding.
Each finding records the offer, brief and rule it used, the source observations and their check dates, its inputs, the date it was produced and its review status.
The five states
| State | Meaning |
|---|---|
| Supported | Applicable evidence satisfies the stated condition, within the limits named in the finding. |
| Mismatch | Applicable evidence contradicts a mandatory condition of the brief. |
| Unresolved | The evidence needed for a decision is missing, incomplete or not yet applicable to the buyer. |
| Conflicting | Sources disagree about the same applicable condition after checking offer, audience, date, scope and billing basis. |
| Not applicable | The condition does not arise for this brief or offer. |
Brief W1
The current checks use brief W1, version 1.0. It describes an illustrative purchase, not a real buyer’s request, and no provider has quoted for it.
| Condition | Status |
|---|---|
| One SaaS web application and the API it consumes | mandatory |
| Two authenticated user roles | mandatory |
| One agreed testing environment | assumed |
| No source code access | mandatory |
| One managed assessment | assumed |
| Manual check of fixes requested 45 days after findings are reported | mandatory |
| A complete, itemized purchase commitment | mandatory |
The four worked checks
These are the checks shown on the homepage, with the rule and inputs behind each finding.
| Purchase condition | What the published terms establish | Question to send the provider |
|---|---|---|
| Two authenticated user rolesMandatory in the brief | Supported · starting amount only Pentest-Tools.com gray box: $5,200 starting amount, calculated as $3,400 + (2 × $900). The complete price for the API, retesting and any additional scope is unresolved. Published formula (Pentest-Tools.com source: Managed web app testing) | “For this app, its API and two roles, what is the complete price, including a manual retest requested 45 days after findings are reported?” |
Rule and provenance: Two authenticated user roles, Pentest-Tools.com · Managed web app testing
| ||
| Manual retest requested on day 45Mandatory in the brief | Mismatch · included request window Astra Expert: outside the included request window. Its two manual re-scans must be requested within 30 days of findings being reported. Extensions are considered case by case. Rescan terms (Astra source: Rescan rules) | “Can you include a manual re-scan requested 45 days after findings are reported? Please confirm the extension and any added cost in writing.” |
Rule and provenance: Manual retest requested on day 45, Astra · Pentest Expert
| ||
| No source code accessMandatory in the brief | Mismatch · source code access Intruder’s listed offer: access mismatch. Its white-box workflow requires connecting a code repository. A different arrangement would need confirmation. Offer and workflow (Intruder source: Pentest pricing) | “Do you offer a test without access to our source code? Please confirm its scope, testing approach and price.” |
Rule and provenance: No source code access, Intruder · AI web app pentest
| ||
| Complete purchase commitmentMandatory in the brief | Unresolved · complete total SynackST: total unresolved. The test starts at $10,283; a platform line item is required, and a free Basic tier is also described. Which tier applies still needs confirming. Platform and test terms (Synack source: Testing packages, platform terms and credit expiry FAQ) | “Can SynackST cover this app and API, and is the Basic platform tier eligible? Please itemize the test, any required platform charge, when purchased credits expire and the full contractual commitment.” |
Rule and provenance: Complete purchase commitment, Synack · SynackST
| ||
Two further examples
The worked checks reach Supported, Mismatch and Unresolved findings. These two examples show the other two states.
| Purchase condition | What the published terms establish | Question to send the provider |
|---|---|---|
| Unused-credit terms for an annual credit packageMandatory in the brief | Conflicting · credit rollover Cobalt Enterprise: rollover terms conflict. The Enterprise comparison table lists rollover of up to 10%; the pricing FAQ says credits do not roll into the next contract. Compare both statements (Cobalt source: Pricing and offer terms, including conflicting rollover statements) | “Which unused-credit term will apply to our Enterprise agreement? Please confirm it in writing.” |
Rule and provenance: Unused-credit terms for an annual credit package, Cobalt · Standard / Premium / Enterprise
| ||
| Tester location or on-site workAssumed in the brief | Not applicable · tester location Tester location: not applicable to this brief. W1 includes no on-site work or contractual location restriction, so the check does not arise. | “If your contract restricts tester location or data handling, add it to your brief and ask every provider the same question.” |
Rule and provenance: Tester location or on-site work, Synack · SynackST
| ||
Rules that protect findings
- If supporting evidence is removed or stops applying, a Supported finding is withdrawn.
- If a required cost is unknown, no total price is given.
- An expired promotion cannot be used as a current price.
- Payment is never an input to any rule.
- Each finding’s state and any amount are recomputed by automated tests. If a source change alters the result, the content checks fail until the finding is reviewed.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Corrections and updates
Each fact is stored once and reused wherever it appears. When a source changes:
- the observation is updated with the new statement, section and check date;
- every comparison cell and finding that depends on it is rechecked, and the content checks fail until each changed finding is resolved; and
- the affected pages show the new check date.
A change to a fact, price, finding or date is a material update and is listed below with its date. Spelling and layout fixes are not listed.
Material updates
| Date | Update |
|---|---|
| October 7, 2026 | Full comparison checked against provider sources. |
| October 8, 2026 | Purchase Check sources rechecked, with Cobalt’s start-time and rollover terms and Synack’s credit-expiry terms. |
| October 8, 2026 | Targeted Intruder price recheck: its pricing page lists $4,000 per test and $3,500 for platform subscribers. The subscriber condition is retained beside the price; the page itself publishes both amounts. |
This record documents the source checks above. A material factual correction or later change to provider terms is added here when published, with the affected information identified. A later provider change is distinguished from a correction to our earlier reporting.
To report an error, follow the correction steps on the contact page. The editorial standards explain how corrections are decided.
Maintenance
- Monthly review schedule: recheck every provider source and the records that depend on it. A check date changes only for facts that were actually rechecked. The dates beside the facts show completed work, not a promise that a scheduled check has already happened.
- Promotions and limited-time terms: checked against their stated expiry and removed when they lapse.
- Reported changes: a correction or a provider update triggers a recheck of the affected source and everything that depends on it.
Guidance and its limits
Our purchasing approach draws on CREST’s penetration testing procurement guidance, particularly specifying requirements and selecting suitable suppliers, and NIST SP 800-115, which addresses planning, conducting and analyzing technical security assessments. The scope checklist identifies the passages consulted for its questions.
These documents inform the questions we ask. They do not endorse this publication, validate the listed providers or establish that an offer meets a current contractual or regulatory requirement. A claim about a requirement must cite the applicable current requirement, not rely on a general or older guidance document.
Citing a finding
Attribute our calculations and applied findings to The PenTest Index, link to the page or specific finding, and preserve the offer, brief, check date and limits that affect the conclusion. Attribute provider terms to the provider’s cited source. A worked starting amount must not be described as a collected quote or complete project price. See the terms of use for reuse.